← Insights / Compliance

Trump's Executive Orders 14179 and 14365 signal federal AI pre-emption—but state laws keep multiplying

The United States is often treated as a single regulatory bloc. For businesses operating internationally, that assumption is becoming increasingly costly. The Trump administration's Executive Orders on AI — 14179 and 14365 — signal a clear federal ambition to consolidate AI policy at the national le

Compliance 26 August 2026 6 min read

Federal vs State: Why the US AI Compliance Picture Is More Complicated Than It Looks

The United States is often treated as a single regulatory bloc. For businesses operating internationally, that assumption is becoming increasingly costly. The Trump administration's Executive Orders on AI — 14179 and 14365 — signal a clear federal ambition to consolidate AI policy at the national level. But state legislatures are not waiting. The result is a compliance environment that is simultaneously centralising and fragmenting, and professional services firms with any US exposure need to understand both forces.

What the Executive Orders Actually Say

Executive Order 14179, issued in January 2025, marked the formal end of the Biden-era AI safety framework. The prior Executive Order on AI safety and security was revoked, and a new direction established: a unified national AI policy oriented around American competitiveness, with the federal government explicitly empowered to evaluate and challenge state AI laws that conflict with federal objectives.

Executive Order 14365, issued later in 2025, reinforced this posture. The federal intent is clear — pre-emption of the existing patchwork of state regulation wherever it is judged to obstruct national AI priorities. Carve-outs exist for state laws covering child safety, data centre infrastructure, and government procurement, but those are narrow exceptions to a broadly assertive federal position.

For businesses, this sounds like good news. A single federal standard would, in theory, simplify compliance planning. But that standard does not yet exist in statutory form, and in the meantime state legislatures have continued legislating regardless.

The State Layer Is Not Going Away

Colorado enacted one of the more ambitious frameworks, with early broad legislation covering high-risk AI systems. Across 2024 and 2025, US states collectively passed laws addressing everything from deepfake criminalisation to algorithmic transparency requirements. The pace has not slowed in response to federal signals.

This creates a genuine operational problem. A professional services firm — an HR consultancy, a law firm, a marketing agency — using AI tools to support client work across multiple US states may simultaneously be subject to different disclosure requirements, different definitions of high-risk AI, and different rules around automated decision-making. Federal pre-emption, if it materialises through litigation or new legislation, may eventually resolve some of this. But that process will take years, and enforcement does not pause for constitutional arguments.

For non-US businesses engaging US clients or operating through US subsidiaries, the instinct to delegate compliance responsibility to local counsel is understandable. It is also insufficient. AI governance decisions — about which tools to deploy, how to document their use, and what disclosures to make to clients — are increasingly being made at the organisational level, not the jurisdictional level.

The FTC Is Refining, Not Retreating

Operation AI Comply, launched by the Federal Trade Commission in September 2024, has produced a useful body of enforcement precedent. Cases against DoNotPay, Evolv, and IntelliVision targeted misleading claims about AI capabilities — robot lawyers that were not, weapon detection that did not work as advertised, facial recognition claims that could not be substantiated.

The more instructive development came in December 2025, when the FTC reopened and set aside a 2024 consent order against Rytr LLC, an AI writing assistant. The Commission determined that the original complaint had not met the legal threshold under the FTC Act and that the order placed undue burden on AI innovation. This is a meaningful signal. The FTC under the current administration is not abandoning AI enforcement — it is refining it around demonstrable harm. Speculative misuse is a harder basis for action. Verifiable false claims remain firmly in scope.

For professional services firms, this matters in a specific way. Any marketing of AI-assisted services — whether that is AI-powered contract review, automated HR analytics, or AI-generated client deliverables — must be accurate. The FTC precedent makes clear that the label matters and the substance must match it.

Canada: A Regulatory Gap With Active Enforcement

Canada's proposed Artificial Intelligence and Data Act, part of Bill C-27, was halted in January 2025 following the prorogation of Parliament. Its reintroduction is expected, with phased enforcement projected 24 to 36 months after royal assent — meaning statutory AI regulation is unlikely to be operational before 2027 at the earliest.

That legislative gap does not mean a compliance gap. The Office of the Privacy Commissioner has been active. In February 2025, the OPC opened an investigation into X Corp.'s data collection practices for AI development. A joint investigation with provincial commissioners, concluded in May 2026, found that OpenAI had failed to obtain express consent for collecting personal information from user interactions for model training, and lacked adequate data retention policies under PIPEDA.

The lesson is direct. Existing privacy law applies to AI systems. The absence of dedicated AI legislation does not create a permissive environment — it means that general privacy and consumer protection frameworks are being applied to AI use cases, often in ways that carry significant compliance risk for organisations that assumed they were operating in a regulatory gap.

Canada has also launched the Canadian AI Safety Institute (CAISI), with a £30 million commitment, and its National AI Strategy — AI for All — published in June 2026 sets out a five-year plan structured around protection, empowerment, adoption, and international cooperation. The direction of travel is toward structured regulation. Firms operating in Canada should be building compliance infrastructure now, not waiting for AIDA to pass.

A Warning From the Courts

Canadian courts recorded 87 decisions involving AI-fabricated legal citations in 2025, up from seven in 2024. The Federal Court has issued and amended guidelines on AI disclosure in legal proceedings. This trend is not exclusive to Canada — similar problems have emerged in US and UK courts.

For law firms, this is an immediate professional conduct issue. For any professional services firm using AI to support research, documentation, or client advice, it is a quality control and liability question. Verification procedures for AI-generated content are no longer optional.

What This Means for International Businesses

The North American compliance picture defies simple summary. Federal pre-emption is an aspiration, not yet a reality. State regulation continues to grow. Canadian statutory AI law is delayed but privacy enforcement is active. Enforcement bodies are sharpening their focus, not standing down.

Professional services businesses with North American clients, operations, or supply chains need a compliance posture that accounts for this complexity — one that does not assume federal uniformity, does not treat legislative delay as regulatory permission, and does not allow AI marketing claims to outrun what the underlying tools actually deliver.

Talk to Ops Intel

Ops Intel works with professional services firms globally to build AI compliance frameworks that are practical, jurisdiction-aware, and built to last beyond the next political cycle. Whether your exposure is to US state law, Canadian privacy obligations, or the growing international frameworks that reference both, we can help you understand where your obligations sit and what you need to do about them.

Contact Ops Intel to arrange a compliance review.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit